ZeroHour
Story · 1 source · 9 articlesfirst updated ()

Cisco Patches Nine Secure Firewall ASA/FTD Vulnerabilities, Including ACL Bypass and Eight Denial-of-Service Flaws

mediumAdvisoryimportance 48
What's new: First merged summary for this story (no previous summary existed). Nine advisories published or updated by Cisco on September 16, 2026 are consolidated into one story; notably, the SSL VPN denial-of-service advisory was expanded that day from the ASAv and FTDv virtual appliances to all ASA and FTD software platforms.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

On September 16, 2026, Cisco released software updates for nine vulnerabilities in Secure Firewall ASA and FTD software: one ACL Object Group Search access control bypass and eight denial-of-service flaws, all exploitable by unauthenticated attackers; the…

Cisco disclosed and patched a batch of vulnerabilities in Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software on September 16, 2026. The most notable is an ACL Object Group Search bypass caused by a logic error in populating group access control policies, which lets an unauthenticated remote attacker send traffic that should be blocked through the device. The other eight advisories describe denial-of-service conditions: improper DTLS resource management on Secure Firewall 3100 and 4200 series devices; a DNS-over-TCP buffer-size tracking error; a TLS 1.3 buffer management flaw in FTD that crashes the LINA process; incomplete SSL certificate validation in FTD's Snort 2 Detection Engine; an IKEv2 certificate authentication logic error; improper rate limiting of syslog message 419002 that drives high CPU under TCP SYN floods; an EIGRP memory-leak flaw exploitable by an adjacent attacker; and system memory or buffer block exhaustion in the VPN and management web servers. All flaws are exploitable by unauthenticated attackers — remote in every case except EIGRP, which requires adjacent access. Cisco has released software updates for all nine; the Snort 2 advisory explicitly states no workarounds are available, and no workarounds or active exploitation are mentioned for the others.

  • Nine Cisco advisories dated September 16, 2026 cover Secure Firewall ASA and FTD software: one access control bypass and eight denial-of-service flaws
  • ACL Object Group Search bypass: a logic error in populating group access control policies lets an unauthenticated remote attacker pass traffic that should be blocked; affects both ASA and FTD
  • DTLS denial of service affects ASA and FTD only on Secure Firewall 3100 and 4200 series; a crafted stream of DTLS traffic forces the device to reload
  • DNS-over-TCP flaw: a logic error mishandling buffer-size tracking lets a crafted DNS reply to a device-originated query restart the TCP DNS response handler and reload the device
  • TLS 1.3 flaw (FTD only): crafted TLS 1.3 packets to a TLS 1.3-enabled listening socket crash the LINA process, with the reload possible before or after connection authentication
  • Snort 2 flaw (FTD only): incomplete SSL certificate validation lets a crafted SSL connection setup request restart the Snort 2 Detection Engine; no workarounds available
  • IKEv2 flaw: a crafted certificate offered during VPN connection setup crashes the IKEv2 process and causes an unexpected device reload
  • Logging flaw: improper rate limiting of syslog message 419002 lets a flood of TCP SYN packets cause high CPU utilization and performance degradation rather than a reload

Coverage timeline

  1. · 2h ago
    Cisco Security Advisories· 32
    Cisco Secure Firewall Threat Defense Software Snort 2 SSL/TLS Denial of Service Vulnerability

    Cisco fixed an SSL certificate parsing flaw in FTD's Snort 2 engine letting unauthenticated remote attackers force detection engine restarts.

  2. · 2h ago
    Cisco Security Advisories· 35
    Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software TCP DNS Denial of Service Vulnerability

    Cisco disclosed a TCP DNS flaw in ASA and FTD firewall software letting unauthenticated remote attackers trigger device reloads and denial of service.

  3. · 2h ago
    Cisco Security Advisories· 28
    Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software EIGRP Denial of Service Vulnerability

    Cisco fixed an EIGRP flaw in Secure Firewall ASA/FTD software letting unauthenticated adjacent attackers trigger memory leaks and unexpected device reloads.

  4. · 2h ago
    Cisco Security Advisories· 48
    Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Object Group Access Control List Bypass Vulnerabilities

    Cisco patched ACL Object Group Search bypass flaws in ASA and FTD firewall software that let unauthenticated attackers reach protected networks.

  5. · 2h ago
    Cisco Security Advisories· 35
    Cisco Secure Firewall Threat Defense Software TLS 1.3 Denial of Service Vulnerability

    A TLS 1.3 buffer management flaw in Cisco Secure Firewall Threat Defense lets remote attackers crash the LINA process and reload devices.

  6. · 2h ago
    Cisco Security Advisories· 28
    Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Logging Denial of Service Vulnerability

    Cisco patched an ASA/FTD rate-limiting flaw where TCP SYN floods trigger excessive syslog 419002 messages, causing high CPU and degraded performance.

  7. · 2h ago
    Cisco Security Advisories· 40
    Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability

    Cisco patched a DTLS flaw in ASA and FTD software for Secure Firewall 3100/4200 series letting unauthenticated attackers trigger device reloads.

  8. · 2h ago
    Cisco Security Advisories· 32
    Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability

    Cisco patched an ASA/FTD IKEv2 certificate authentication flaw letting unauthenticated remote attackers crash the IKEv2 process and reload devices with crafted certificates.

  9. · 2h ago
    Cisco Security Advisories· 45
    Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability

    Cisco expanded an SSL VPN denial-of-service advisory to cover all ASA and FTD software platforms; unauthenticated attackers can exhaust device memory.